A one-day programme on Bank Negara Malaysia's Risk Management in Technology (RMiT) policy document, for staff at licensed banks, Islamic banks, investment banks, insurers and takaful operators, development financial institutions, electronic money issuers and payment system operators. RMiT is a supervisory expectation with teeth: it names the governance structures that must exist, the control standards technology must meet, the testing that must be performed, and the events that must be reported to the Bank within 24 hours.
The programme works through those requirements as an internal compliance exercise rather than a reading of the policy document. Participants finish by scoring their own institution against the control domains covered and identifying where the evidence for compliance does not yet exist. Content can be tailored to the institution's licence category and to the audience's mix of technology, risk and audit roles.
HRD Corp SBL-Khas Claimable
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
RMiT: Scope, Structure and Supervisory Expectations
Which institutions RMiT applies to and how it relates to the Bank's other policy documents on outsourcing, business continuity and operational risk. How RMiT compliance is examined in practice, the difference between a standard and a guidance paragraph, and what supervisors typically ask for first.
10:15 AM - 11:15 AM
Governance and Oversight
Board and senior management responsibilities, the Technology Risk Management Framework and the Cyber Resilience Framework, the role and independence of the Chief Information Security Officer, the three lines of defence applied to technology risk, and the technology risk appetite statement and how it is meant to bite on real decisions.
11:15 AM - 11:30 AM
Break
11:30 AM - 12:30 PM
Technology Operations and Resilience
Data centre and network resilience, capacity management, change and patch management, the availability expectation for critical systems and the associated unscheduled downtime reporting duty, recovery time and recovery point objectives, and disaster recovery testing that produces usable evidence.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:30 PM
Cyber Security Controls
Access control and privileged access management, cryptography and key management, the security operations centre, threat intelligence and industry information sharing, vulnerability management, penetration testing and adversarial attack simulation, and the heightened control expectations for internet-facing and customer-facing systems.
2:30 PM - 3:15 PM
Cloud, Third Parties and Outsourcing
Supervisory expectations before adopting cloud services for critical systems, the risk assessment and prior engagement with the Bank, concentration risk, exit strategy and portability, and the contractual, access and audit rights an institution needs over its technology service providers.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:15 PM
Incident Management and Reporting to the Bank
Classification of technology and cyber incidents, the 24-hour notification duty, the content of the initial notification and of the follow-up report, coordination between the security operations centre, business continuity and communications, and the post-incident review the Bank will expect to see.
4:15 PM - 4:45 PM
Self-Assessment Workshop
Participants score their own institution against the RMiT control domains covered during the day, identify the three weakest, and assign owners.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate, suitable for IT, information security, technology risk, operational risk, compliance and internal audit staff at BNM-regulated institutions
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment 10 to 15 question knowledge assessment covering all modules
Certificate Certificate of Completion issued to all participants upon full attendance